AWS Certified Solutions Architect - Associate (SAA-C03) โ Questions and Answers
Question 1: Which AWS service enables you to create a pilot-light disaster recovery strategy by maintaining a minimal version of your environment running in a secondary Region?
- AWS Backup
- Amazon Data Lifecycle Manager
- AWS CloudFormation StackSets
- AWS Elastic Disaster Recovery (Correct answer)
Correct answer: AWS Elastic Disaster Recovery
AWS Elastic Disaster Recovery (DRS) continuously replicates source servers to a staging area and can quickly scale up a full environment in a secondary Region during a disaster.
Question 2: An application needs to distribute incoming TCP traffic across multiple EC2 instances and requires support for static IP addresses. Which load balancer type should be used?
- Classic Load Balancer
- Gateway Load Balancer
- Application Load Balancer (ALB)
- Network Load Balancer (NLB) (Correct answer)
Correct answer: Network Load Balancer (NLB)
Network Load Balancer operates at Layer 4, supports static and Elastic IP addresses, and handles millions of TCP requests per second with ultra-low latency.
Question 3: What AWS feature allows an Auto Scaling group to replace unhealthy EC2 instances automatically without manual intervention?
- Scheduled scaling
- Health check replacement (Correct answer)
- Predictive scaling
- Target tracking
Correct answer: Health check replacement
Auto Scaling groups perform periodic health checks and automatically terminate and replace any instance that fails the check.
Question 4: You are using AWS CloudFormation Designer to work on a complicated stack that was created with CloudFormation. You want to use as little of the available workspace as possible in the designer. Which functionality should you use if you want to hide the left sidebar?
- Create a new stack in another window and drag its resources to the original window.
- Use keyboard shortcuts to hide the left sidebar.
- Click on the Collapse View button (left sidebar hide/show icon in the top-left corner). (Correct answer)
- Close down AWS CloudFormation Designer and reopen it.
Correct answer: Click on the Collapse View button (left sidebar hide/show icon in the top-left corner).
When additional workspace is required, the visibility of the left sidebar can be toggled by clicking the Collapse View button (left sidebar hide/show icon) in the top-left corner of the CloudFormation Designer window. This provides additional space when it is required.
Question 5: To handle HTTP requests, an application hosted on EC2 instances communicates with the ELB. The X-Forwarded-For header of each request includes three IP addresses. Which of these IP addresses will be included in the header?
- IP address of ELB (Correct answer)
- IP address of client
- IP address of CloudWatch
- IP address of Forward Request
Correct answer: IP address of ELB
When using an HTTP/HTTPS load balancer, the X-Forwarded-For request header can be used to determine the client's IP address. Your server access logs will only show the IP address of the load balancer because it is what intercepts communication between clients and servers. The client's IP address is recorded in the X-Forwarded-For request header and forwarded to your server using Elastic Load Balancing.
Question 6: What is the purpose of Amazon S3 Intelligent-Tiering storage class?
- To encrypt all stored objects by default
- To automatically move objects between access tiers based on changing access patterns, optimizing cost (Correct answer)
- To replicate objects across three Regions automatically
- To provide the lowest possible latency for all S3 objects
Correct answer: To automatically move objects between access tiers based on changing access patterns, optimizing cost
S3 Intelligent-Tiering monitors object access and automatically moves objects between Frequent and Infrequent Access tiers (and archive tiers) to save costs without performance impact.
Question 7: Which AWS Well-Architected Framework pillar specifically addresses the ability to protect information, systems, and assets while delivering business value?
- Security (Correct answer)
- Operational Excellence
- Reliability
- Performance Efficiency
Correct answer: Security
The Security pillar of the AWS Well-Architected Framework covers protecting information, systems, and assets through risk assessments and mitigation strategies.
Question 8: Which defense-in-depth approach should an architect use to protect an application that requires both web-tier and database-tier security?
- Apply a single NACL to the entire VPC
- Place all resources in the same security group
- Use separate security groups for web and database tiers with the DB group only allowing traffic from the web group (Correct answer)
- Use AWS WAF to protect both the web and database layers
Correct answer: Use separate security groups for web and database tiers with the DB group only allowing traffic from the web group
Tiered security groups implement defense in depth by ensuring the database tier only accepts traffic explicitly from the web tier, not from any external source.
Question 9: What is the Plan-Do-Check-Act (PDCA) cycle in Architecting on AWS Certification quality management?
- A one-time project completion checklist
- An employee performance rating system
- A financial budgeting methodology
- An iterative four-step method for continuous improvement of processes and products (Correct answer)
Correct answer: An iterative four-step method for continuous improvement of processes and products
PDCA is a continuous improvement cycle: Plan a change or test, Do implement it on a small scale, Check measure the results, Act adopt or adjust based on findingsโthen repeat.
Question 10: What is the primary benefit of using Amazon Aurora Serverless v2 compared to a provisioned Aurora cluster for a variable-workload application?
- It replicates data to three Regions automatically
- It provides a lower storage cost per GB
- It eliminates the need for database backups
- It automatically scales compute capacity up and down based on demand, eliminating over-provisioning (Correct answer)
Correct answer: It automatically scales compute capacity up and down based on demand, eliminating over-provisioning
Aurora Serverless v2 scales compute in fine-grained increments (0.5 ACU) almost instantly, so you pay only for the capacity used rather than provisioning for peak load.
Question 11: Which AWS service allows you to privately connect your VPC to supported AWS services without requiring an internet gateway, NAT device, or VPN connection?
- VPC Endpoints (Correct answer)
- AWS Transit Gateway
- VPC Peering
- AWS PrivateLink
Correct answer: VPC Endpoints
VPC Endpoints (both Gateway and Interface types) enable private connectivity between your VPC and AWS services without traffic leaving the Amazon network.
Question 12: An operations team must track software inventory โ installed packages, OS version, and running services โ across 1,000 EC2 instances. Which AWS service collects this data without requiring custom scripts?
- AWS Config
- AWS Systems Manager Inventory (Correct answer)
- Amazon Inspector
- AWS CloudTrail
Correct answer: AWS Systems Manager Inventory
SSM Inventory collects metadata about installed applications, network configurations, and running services from managed instances and stores results in S3 or Systems Manager.
Question 13: Which alloying element in nickel-base superalloy filler metals is primarily responsible for their high-temperature strength and oxidation resistance?
- Tungsten
- Cobalt
- Chromium (Correct answer)
- Molybdenum
Correct answer: Chromium
Chromium forms a protective Cr2O3 oxide scale that provides oxidation resistance and also solid-solution strengthens the nickel matrix at elevated temperatures.
Question 14: An application requires a shared file system accessible by multiple EC2 instances simultaneously across multiple Availability Zones. Which storage solution should be used?
- Instance Store
- Amazon EBS gp3
- Amazon S3
- Amazon EFS (Correct answer)
Correct answer: Amazon EFS
Amazon EFS is a fully managed NFS file system that can be mounted concurrently by multiple EC2 instances across AZs.
Question 15: An architect is choosing between Amazon EBS gp2 and gp3 volumes. Which statement about gp3 is correct from a cost and performance perspective?
- gp3 is more expensive but offers guaranteed IOPS
- gp3 requires Multi-Attach to improve performance
- gp3 is cheaper than gp2 and allows IOPS and throughput to be configured independently (Correct answer)
- gp3 has lower maximum IOPS than gp2
Correct answer: gp3 is cheaper than gp2 and allows IOPS and throughput to be configured independently
gp3 volumes are approximately 20% cheaper than gp2 per GB-month and allow you to provision up to 16,000 IOPS and 1,000 MB/s throughput independently of volume size.
Question 16: Which S3 storage class is the most cost-effective for data that is accessed infrequently but must be retrieved within milliseconds?
- S3 One Zone-IA
- S3 Glacier Instant Retrieval
- S3 Standard
- S3 Standard-Infrequent Access (Correct answer)
Correct answer: S3 Standard-Infrequent Access
S3 Standard-IA offers lower storage costs than S3 Standard with millisecond retrieval, designed for data accessed less than once a month.
Question 17: What is evidence-based practice in Architecting on AWS Certification welding metallurgy & materials?
- Following only personal experience and gut instinct
- Using only the newest unproven methods available
- Doing whatever the client specifically requests without question
- Integrating the best available research evidence with professional expertise and client needs (Correct answer)
Correct answer: Integrating the best available research evidence with professional expertise and client needs
Evidence-based practice combines rigorous research evidence, professional expertise, and client preferences to make informed decisions that optimize outcomes.
Question 18: An architect is deploying a content-heavy website and wants to reduce origin server load. After enabling CloudFront, which cache behavior setting maximizes cache hit ratio?
- Minimize the number of headers and query strings forwarded to origin (Correct answer)
- Forward all headers and query strings to origin
- Disable caching entirely for dynamic pages
- Set the TTL to 0 for all objects
Correct answer: Minimize the number of headers and query strings forwarded to origin
Forwarding fewer headers and query strings increases the likelihood that multiple requests match the same cached object, raising the cache hit ratio and reducing origin requests.
Question 19: An application serves static assets globally. Which AWS service reduces latency for users worldwide by caching content at edge locations?
- Elastic Load Balancing
- Amazon API Gateway
- Amazon CloudFront (Correct answer)
- AWS Global Accelerator
Correct answer: Amazon CloudFront
Amazon CloudFront is a CDN that caches content at 400+ Points of Presence globally, reducing origin load and delivering assets from the nearest edge location.
Question 20: A company wants to replicate an on-premises Active Directory to AWS for authentication of EC2 instances. Which service provides a managed Microsoft AD in the cloud?
- Amazon Cognito
- AWS IAM
- AWS IAM Identity Center
- AWS Directory Service for Microsoft Active Directory (Correct answer)
Correct answer: AWS Directory Service for Microsoft Active Directory
AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD) provisions a fully managed AD domain in AWS.
Question 21: What is the purpose of an Amazon Aurora cluster's reader endpoint?
- It load-balances read traffic across all Aurora replicas (Correct answer)
- It routes writes to the primary instance only
- It provides a static IP for the cluster
- It connects to the cluster from outside the VPC
Correct answer: It load-balances read traffic across all Aurora replicas
The Aurora reader endpoint automatically distributes read connections across all available Aurora Replicas, reducing load on the primary writer instance.
Question 22: Which ELB listener rule action allows an Application Load Balancer to return a static error page when the backend targets are all unhealthy?
- Authenticate action
- Redirect action
- Fixed-response action (Correct answer)
- Forward action
Correct answer: Fixed-response action
The ALB fixed-response action returns a custom HTTP response (status code + body) directly from the load balancer without routing to any target.
Question 23: Which EC2 instance purchasing model is best suited for a batch processing workload that can tolerate interruptions in exchange for the lowest possible cost?
- Spot Instances (Correct answer)
- Dedicated Instances
- Reserved Instances
- On-Demand Instances
Correct answer: Spot Instances
EC2 Spot Instances use spare AWS capacity at up to 90% discount; they can be interrupted with a 2-minute warning, making them ideal for fault-tolerant batch jobs.
Question 24: Which AWS service enables forensic investigation of security incidents by visualizing relationships between resources, IPs, and user accounts over time?
- Amazon Inspector
- Amazon Detective (Correct answer)
- AWS Security Hub
- AWS CloudTrail Lake
Correct answer: Amazon Detective
Amazon Detective automatically collects log data and uses ML to build an interactive graph model for investigating and visualizing security incidents.
Question 25: Which AWS Global Infrastructure feature ensures that an EC2 instance placed in a specific Availability Zone is physically isolated from instances in other AZs within the same Region?
- Placement groups
- VPC peering
- AZ physical separation (Correct answer)
- Security groups
Correct answer: AZ physical separation
Each Availability Zone is a physically distinct location with independent power, cooling, and networking, providing fault isolation from other AZs in the Region.
Question 26: Which Route 53 routing policy sends traffic to the healthiest endpoint and can automatically failover when a primary endpoint becomes unhealthy?
- Failover routing (Correct answer)
- Latency routing
- Geolocation routing
- Weighted routing
Correct answer: Failover routing
Route 53 Failover routing directs traffic to a primary resource and automatically routes to a secondary resource when health checks detect a failure.
Question 27: Which Amazon RDS feature automatically creates a standby replica in a different Availability Zone and promotes it if the primary fails?
- Multi-AZ deployment (Correct answer)
- Read Replicas
- Aurora Global Database
- RDS Proxy
Correct answer: Multi-AZ deployment
RDS Multi-AZ maintains a synchronous standby replica in a different AZ and automatically fails over to it during outages.
Question 28: What is the primary purpose of an AWS Service Control Policy (SCP) in AWS Organizations?
- Define guardrails for maximum permissions in member accounts (Correct answer)
- Configure VPC flow logs
- Grant IAM permissions to users
- Enable cross-account role assumption
Correct answer: Define guardrails for maximum permissions in member accounts
SCPs set permission guardrails that limit what actions can be performed in member accounts, regardless of IAM policies.
Question 29: Which Amazon EC2 feature allows multiple instance types to be used within the same Auto Scaling group, enabling lower cost by mixing On-Demand and Spot capacity?
- Mixed Instances Policy (Correct answer)
- Placement groups
- Burstable instances
- Dedicated Tenancy
Correct answer: Mixed Instances Policy
Mixed Instances Policy in Auto Scaling lets you specify multiple instance types and blend On-Demand and Spot Instances to optimize cost and availability simultaneously.
Question 30: Under PCI DSS Requirement 10, cardholder data environment (CDE) activity must be logged and protected. Which combination best satisfies this on AWS?
- CloudTrail + S3 with MFA Delete and Object Lock (Correct answer)
- AWS Shield + WAF access logs
- VPC Flow Logs + CloudWatch Logs only
- AWS Config + Trusted Advisor
Correct answer: CloudTrail + S3 with MFA Delete and Object Lock
CloudTrail captures API activity for the CDE, while S3 Object Lock (WORM) and MFA Delete prevent log tampering, meeting PCI DSS Requirement 10 integrity controls.
AWS Certified Solutions Architect - Associate (SAA-C03)
The AWS Certified Solutions Architect - Associate exam validates the ability to design and implement distributed systems on AWS, covering secure, resilient, high-performing, and cost-optimized architectures. It targets individuals with at least one year of hands-on experience designing AWS cloud solutions.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong โ answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds